Yeni: Müşterileriniz artık paketinin nerede olduğunu sizin mağaza adınızla açılan bir sayfadan görebiliyor.Göz atın →

Data Processing Agreement

This agreement governs how AKIN INDUSTRIES LLC processes the personal data of your buyers on your behalf when you use Custombull. It forms part of the Terms of Service.

Last updated: Version: 1.0AKIN INDUSTRIES LLCTürkçe sürüm

In short

  • For buyer data in your orders, tracking page messages, customer messages and Marketing Center contacts, you are the controller and we are your processor.
  • We process that data only on your instructions and to provide the service. We do not sell it, use it for our own purposes or combine it with other data.
  • Our subprocessor categories are public and the full list with names is available to you on request. We give 30 days' notice before adding a new subprocessor, and you can object.
  • If we become aware of a personal data breach, we notify you without undue delay and within 48 hours at the latest.
  • For transfers from the EU, UK and Switzerland, the EU Standard Contractual Clauses and the UK Addendum are incorporated by reference. No separate signature is needed.

This summary is for convenience only and is not binding. The full text below governs.

Contents
  1. 1. Parties, effect and order of precedence
  2. 2. Definitions
  3. 3. Roles of the parties
  4. 4. Annex 1: Details of processing
  5. 5. Documented instructions
  6. 6. Confidentiality
  7. 7. Security (GDPR Art. 32) and Annex 2
  8. 8. Subprocessors
  9. 9. Assistance with data subject requests
  10. 10. Assistance with security, impact assessments and consultation
  11. 11. Personal data breach notification
  12. 12. Deletion or return at the end of processing
  13. 13. Information and audits
  14. 14. International transfers
  15. 15. Customer obligations
  16. 16. US state privacy law commitments
  17. 17. Data processor obligations under KVKK
  18. 18. Liability
  19. 19. Term, termination and changes

1. Parties, effect and order of precedence

This Data Processing Agreement ("DPA") is entered into between the seller who holds a Custombull account ("Customer") and AKIN INDUSTRIES LLC, 11500 Main St. Suite 126, Houston, TX 77025, United States of America ("Custombull", "we").

The Customer accepts this DPA by accepting the Terms of Service, and it remains in effect for as long as the Terms do. A Customer who wants a countersigned copy can write to hello@custombull.com.

In case of conflict, the following order applies: (1) the Standard Contractual Clauses and their annexes, (2) this DPA, (3) the Terms of Service.

2. Definitions

  • Data Protection Laws: all laws that apply to the processing of personal data, in particular the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK), the California Consumer Privacy Act as amended (CCPA/CPRA), the Texas Data Privacy and Security Act (TDPSA) and other US state privacy laws.
  • Customer Personal Data: personal data that Custombull processes on behalf of the Customer under this DPA, as described in Annex 1.
  • Controller, processor, data subject, processing, personal data breach: have the meanings given in the Data Protection Laws. "Processor" includes a "data processor" under KVKK, a "service provider" under the CCPA and a "processor" under the TDPSA.
  • Subprocessor: any third party engaged by Custombull to process Customer Personal Data.
  • SCCs: the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • UK Addendum: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (ICO).

3. Roles of the parties

For Customer Personal Data, the Customer is the controller and Custombull is the processor. If the Customer itself acts as a processor for another controller, the Customer confirms that it is authorized to engage Custombull as a subprocessor.

Custombull is a controller for seller account data, billing, visitors to this website and newsletter subscribers. That processing is governed by our Privacy Policy and is outside the scope of this DPA.

Custombull may also process Customer Personal Data to keep the service secure, to prevent fraud and abuse and to comply with legal obligations that apply to it, limited to what is necessary for those purposes.

4. Annex 1: Details of processing

ItemDetails
Subject matterProduction, shipping and tracking of orders from marketplaces the Customer connects; communication with buyers; marketing sends by the Customer to its own customers
Nature of processingCollection (through marketplace APIs and the tracking page), recording, storage, organization, transmission to contracted producers and shipping providers, message delivery, engagement measurement, deletion and anonymization
PurposeProviding the service described in the Terms: order import, matching the correct design, printing by contracted producers in the United States, quality control, shipping labels, reporting tracking to the marketplace, the order tracking page, messages and reply suggestions, Marketing Center campaigns and attribution reports
DurationThe term of the Terms of Service, plus the deletion period in section 12 of this DPA
Categories of data subjectsThe Customer's buyers and shipping recipients; people who use the tracking page; the Customer's prospects; people on the Customer's marketing lists
Categories of personal dataBuyer name; shipping address; email and phone where the marketplace provides them; order contents and amounts; personalization text and images; tracking page questions and personalization requests; marketplace messages and attachments; Marketing Center contact lists, consent records, segments, email and SMS delivery, open and click events, campaign attribution records
Sensitive dataNot intentionally processed. The Customer agrees not to send sensitive data in personalization or messages unless it is strictly needed to fulfill the order
Frequency of transferContinuous, depending on use of the service
SubprocessorsThe list published on the Subprocessors page

5. Documented instructions

Custombull processes Customer Personal Data only on the Customer's documented instructions (GDPR Art. 28(3)(a)). The Terms, this DPA, the settings and choices the Customer makes in the service (for example connecting a shop, sending a campaign, or turning on "auto publish" in Automated Production) and the Customer's written requests are instructions.

If applicable law requires other processing, Custombull will inform the Customer before processing unless that law prohibits it. If Custombull believes an instruction infringes Data Protection Laws, it will inform the Customer immediately and may suspend that instruction until the Customer confirms or changes it.

6. Confidentiality

Custombull ensures that employees and contractors authorized to access Customer Personal Data are bound by contractual or statutory confidentiality, and limits access to the people and the extent their role requires (GDPR Art. 28(3)(b)).

7. Security (GDPR Art. 32) and Annex 2

Custombull applies the technical and organizational measures below to ensure a level of security appropriate to the risk. Custombull may improve these measures over time but will not reduce the overall level of security.

Annex 2: Technical and organizational measures
AreaMeasure
Transport securityAll traffic is encrypted in transit with TLS
SecretsCredentials and marketplace access tokens are stored encrypted; tokens are revoked and deleted when a connection is removed
AuthenticationPasswords are hashed; TOTP two factor authentication is mandatory for seller accounts and comes with recovery codes; repeated failed logins are throttled
AuthorizationSub user permissions are fail closed: anything not explicitly granted is denied; team members can work without seeing order or finance data
Access controlAccess to production systems is restricted, logged and reviewed; least privilege applies
File accessArtwork and production files are served only through short lived signed links; tracking pages use unguessable links and do not show costs or internal notes
ContinuityEncrypted backups are taken on rotation and fully replaced within 30 days
Abuse preventionRate limiting, quota enforcement, error tracking and audit logs
Data minimizationPrompts for AI listing content do not include buyer personal data; reply suggestions include only the relevant message text; form inputs are masked in error reports
Subprocessor oversightSubprocessors are engaged under written obligations at least as protective as this DPA

As of the date of this DPA, Custombull does not claim any independent security certification (such as SOC 2 or ISO 27001). If one is obtained, it will be announced on this page.

8. Subprocessors

  1. The Customer gives Custombull general written authorization to engage Subprocessors (GDPR Art. 28(2)). Subprocessor categories, processing locations and transfer safeguards are published on the Subprocessors page. The full list of Subprocessors in place on the date of this DPA, with their names, is provided to the Customer on request under a duty of confidentiality at hello@custombull.com, and the Subprocessors on that list are deemed approved. The Customer uses the full list only to exercise its rights under this DPA and meet its own data protection obligations, and may disclose it to its data subjects and supervisory authorities as needed.
  2. At least 30 days before adding or replacing a Subprocessor, Custombull will notify the Customer by account email or in-app notice of the Subprocessor's name, purpose and location, and update the published categories where needed.
  3. The Customer may object on reasonable data protection grounds within that period by writing to hello@custombull.com. The parties will work in good faith toward a solution. If none is found, the Customer may terminate the affected service by notice, and any prepaid subscription fees for the period after termination takes effect will be refunded pro rata.
  4. Custombull imposes on each Subprocessor data protection obligations that are in substance the same as those in this DPA and remains liable to the Customer for its Subprocessors' performance (GDPR Art. 28(4)).
  5. Where urgent security or continuity needs require it, a Subprocessor may be replaced on shorter notice. The Customer will be informed as soon as possible and keeps the same right to object.

Contracted producers and carriers: the independent print businesses in the United States that produce orders, and shipping providers and carriers, receive only the data needed to produce and deliver the order. Carriers (USPS, UPS, FedEx) transport parcels under their own legal obligations and may act as independent parties under their own terms while doing so.

9. Assistance with data subject requests

Taking into account the nature of the processing, Custombull assists the Customer with appropriate technical and organizational measures in responding to data subject requests (access, rectification, erasure, restriction, portability, objection and their US state law equivalents) (GDPR Art. 28(3)(e)). The Customer can view, export and delete orders and contacts in the application.

If Custombull receives a request directly from a buyer, it will not respond on the merits unless required by law, will refer the person to the Customer and will forward the request to the Customer without undue delay. Opt-outs from marketing messages are applied immediately to protect the recipient and added to the suppression list.

10. Assistance with security, impact assessments and consultation

Taking into account the nature of the processing and the information available to it, Custombull provides reasonable assistance to the Customer with its obligations under GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation with a supervisory authority). For extensive assistance beyond the ordinary scope of this DPA, Custombull may charge a reasonable fee notified in advance.

11. Personal data breach notification

Custombull will notify the Customer by account email without undue delay and in any event within 48 hours after becoming aware of a personal data breach affecting Customer Personal Data. The initial notice will include, to the extent then known:

  • the nature of the breach, the categories of data affected and the approximate number of data subjects and records,
  • a contact point at Custombull,
  • the likely consequences of the breach,
  • the measures taken or proposed.

Where information cannot be provided at once, it will be provided in phases without undue delay. The notice is intended to help the Customer meet its own obligations to notify supervisory authorities within 72 hours (GDPR Art. 33 and the equivalent KVKK Board decision) and affected individuals. Notification by Custombull is not an acknowledgment of fault or liability.

12. Deletion or return at the end of processing

When the Terms end or the Customer deletes its account, Custombull deletes or anonymizes Customer Personal Data within 30 days (GDPR Art. 28(3)(g)). Before that period ends, the Customer can export its orders and contacts in a commonly used format from the application or on request. Copies in encrypted backups are purged automatically within 30 days through the backup rotation.

Data that applicable law requires us to keep (for example tax and accounting records and the minimum order record needed to prove a shipment: order number, date, amount and tracking number) is kept only for that purpose, for the required period and in confidence.

13. Information and audits

Custombull makes available, on the Customer's reasonable request, the information necessary to demonstrate compliance with this DPA (GDPR Art. 28(3)(h)). Compliance is demonstrated first through written information, a description of security measures and answers to questionnaires.

If that information is not sufficient, or a supervisory authority requires it, the Customer may carry out an audit no more than once a year, with at least 30 days' written notice, during normal business hours, through an independent auditor bound by confidentiality, and in a way that does not compromise the data or security of Custombull's other customers. The Customer bears the audit costs unless the audit reveals a material breach. The annual limit does not apply after a breach or at the request of a supervisory authority.

14. International transfers

Custombull is established in the United States; its servers are in the European Union and most of its Subprocessors are in the United States. Custombull does not claim participation in the EU-US Data Privacy Framework. Transfers rely on the mechanisms below.

EU and European Economic Area

For transfers of Customer Personal Data subject to the GDPR to a country without an adequacy decision, SCCs Module 2 (controller to processor) are incorporated into this DPA by reference and are deemed entered into when the Customer accepts the Terms. The Customer is the data exporter and Custombull is the data importer. For onward transfers to its Subprocessors, Custombull uses SCCs Module 3 (processor to processor) or an equivalent transfer mechanism. The following options apply:

SCC clauseOption
Clause 7 (docking clause)Included
Clause 9(a) (subprocessors)Option 2: general written authorization, with 30 days' notice
Clause 11(a) (redress)The optional independent dispute resolution body does not apply
Clause 13 (supervision)The competent supervisory authority determined by the Customer's establishment or EU representative
Clause 17 (governing law)Option 1: the law of Ireland
Clause 18(b) (forum)The courts of Ireland
Annex IAnnex 1 of this DPA and the party details in section 1
Annex IIAnnex 2 of this DPA (security measures)
Annex IIIThe Subprocessors page

United Kingdom

For transfers subject to the UK GDPR, the ICO International Data Transfer Addendum (version B1.0, in force from 21 March 2022) is incorporated by reference and supplements the SCCs. Table 1 party details are in section 1; Table 2 selections are in the SCC table above; Table 3 appendices are Annexes 1 and 2 of this DPA; for Table 4, either party may end the Addendum.

Switzerland

For transfers subject to the Swiss FADP, the SCCs apply with these adaptations: the competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC); the term "member state" is not to be interpreted so as to exclude data subjects in Switzerland from suing in their place of habitual residence; references to the GDPR are read as references to the FADP.

Türkiye

For transfers from Türkiye under Article 9 of KVKK, Custombull agrees on the Customer's request to sign the standard contract published by the Turkish Personal Data Protection Board. Notifying the Board of the standard contract within 5 business days of signature is the obligation of the Customer as the transferring party; Custombull will provide the information needed.

15. Customer obligations

  • Have a valid legal basis under Data Protection Laws to collect Customer Personal Data and to have Custombull process it.
  • Give buyers and other data subjects the required notice that their data will be processed by Custombull and its Subprocessors (for example in the shop's privacy policy).
  • Obtain and be able to prove the consent needed for every email, SMS and WhatsApp message sent through the Marketing Center: in the United States, the CAN-SPAM Act (accurate sender information, non-deceptive subject lines, a physical postal address, a working opt-out, and honoring opt-outs within 10 business days) and the TCPA (prior express written consent for automated marketing texts, respecting quiet hours and STOP requests); in the EU and UK, the GDPR and ePrivacy rules (including PECR); in Türkiye, KVKK, Law No. 6563 and registration with the Commercial Message Management System (IYS) where required; in Canada, CASL.
  • Comply with Meta's WhatsApp Business policies for WhatsApp messages.
  • Ensure that its instructions to Custombull comply with Data Protection Laws and not send sensitive data unnecessarily.
  • Respond to buyer requests on time and, where required, notify supervisory authorities and individuals of breaches.

16. US state privacy law commitments

Where Customer Personal Data is subject to US state privacy laws such as the CCPA/CPRA or the TDPSA, Custombull acts as a service provider or processor and commits to:

  • Not sell Customer Personal Data and not share it for cross context behavioral advertising.
  • Not retain, use or disclose it for any purpose other than the business purposes in the Terms, or outside the direct business relationship with the Customer.
  • Not combine it with personal data received from others or collected on its own, except as the law permits.
  • Notify the Customer if it determines it can no longer meet its obligations, and allow the Customer to take reasonable steps to stop and remediate unauthorized use.
  • Under the TDPSA (Texas Business and Commerce Code Section 541.104): follow the Customer's instructions, ensure that people processing the data are bound by confidentiality, delete or return the data at the end of the service as the Customer directs, make available the information needed to demonstrate compliance, and bind subcontractors to the same obligations by written contract.

17. Data processor obligations under KVKK

Under Article 12(2) of KVKK, Custombull is jointly responsible with the Customer for the security of Customer Personal Data and takes the measures in Article 12(1). Custombull will not disclose personal data it learns to others in breach of this DPA and KVKK, and will not use it outside the purpose of processing. This obligation survives the end of the engagement (Article 12(4)).

18. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Those limitations do not affect liability to data subjects under the SCCs, liability that cannot be limited under Data Protection Laws, or any other mandatory law.

19. Term, termination and changes

This DPA remains in effect as long as the Terms are in effect and Custombull processes Customer Personal Data, and ends automatically when Custombull has deleted or returned that data. Provisions that by their nature should survive (confidentiality, deletion, liability) survive.

Custombull may update this DPA to reflect changes in Data Protection Laws, a new transfer mechanism, or changes that do not disadvantage the Customer. Material changes will be announced by email or in-app notice 30 days before they take effect. No change may reduce the protection required by Data Protection Laws.

The English version of this DPA governs; the Turkish version is a translation. Where mandatory law gives priority to a local language version, that rule applies. The SCCs and the UK Addendum apply in their official texts.

Contact

For any question or request about this document, email hello@custombull.com. Postal address: AKIN INDUSTRIES LLC, 11500 Main St. Suite 126, Houston, TX 77025, United States of America.

Other legal documents

The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.

Back to top

Ücretsiz başla